First published: Fri Apr 17 2015(Updated: )
OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
pip/swift | <2.3.0 | 2.3.0 |
OpenStack Swift3 | <=2.2.2 | |
Ubuntu Linux | =12.04 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =15.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1856 is considered a moderate severity vulnerability.
To fix CVE-2015-1856, upgrade OpenStack Object Storage (Swift) to version 2.3.0 or later.
CVE-2015-1856 affects OpenStack Object Storage (Swift) versions prior to 2.3.0.
CVE-2015-1856 is a privilege escalation vulnerability that allows remote authenticated users to delete object versions.
No, CVE-2015-1856 requires that the attacker is a remote authenticated user.